Improper Certificate Validation in wolfSSL - CVE-2026-93302

 

Improper Certificate Validation in wolfSSL - CVE-2026-93302

Published: October 5, 2026


Vulnerability identifier: #VU153281
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-93302
CWE-ID: CWE-295
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass peer authentication.

The vulnerability exists due to improper certificate validation in the trusted peer certificate verification path when processing a peer certificate. A remote attacker can present a forged certificate that reuses trusted certificate identity fields to bypass peer authentication.

Exploitation requires knowledge of the CA certificates loaded as trusted peer certificates.


Affected software

wolfSSL

How to mitigate CVE-2026-93302

Install security update from vendor's website.

wolfSSL - update to 5.9.4

External References

Related Security Bulletins